All 33 CVE vulnerabilities found in LearnPress – WordPress LMS Plugin for Create and Sell Online Courses, with AI-generated Chinese analysis, references, and POCs.
This page documents security vulnerabilities associated with the LearnPress WordPress LMS Plugin, categorized under weak encryption and server-side request forgery weaknesses. It serves as a centralized repository for tracking known security issues affecting this specific learning management system extension. The content collected here aggregates advisory data and vulnerability reports spanning from the initial release of the plugin through to the most recent updates in 2024. By organizing these records chronologically and categorically, the page provides a structured view of the product's security posture over time. Users exploring this page can discover detailed insights into how the vendor has responded to various security advisories and patches. The aggregation allows researchers and administrators to track the evolution of the vendor's security practices and understand recurring patterns within specific weakness classes such as input validation errors or insufficient access controls. Furthermore, individuals can look up the complete vulnerability history of the LearnPress plugin to assess the impact on their own installations. This historical data is crucial for making informed decisions about system updates, migration strategies, or additional security hardening measures. The page does not merely list isolated incidents but presents them as part of a broader narrative regarding the product's development lifecycle and security maturity. Readers can analyze how quickly patches were released relative to disclosure and identify any gaps in the vendor's security communication process. This comprehensive overview supports proactive risk management by highlighting persistent or recurring security flaws that may require immediate attention beyond standard update cycles.
Vendor: thimpress
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2023-6567 | LearnPress <= 4.2.5.7 - Unauthenticated SQL Injection via order_by CWE-89 | 9.8 | Critical | 2024-01-11 |
| CVE-2023-6634 | LearnPress <= 4.2.5.7 - Command Injection CWE-88 | 8.1 | High | 2024-01-11 |
| CVE-2023-6223 | LearnPress <= 4.2.5.7 - Insecure Direct Object Reference to Information Disclosure CWE-639 | 4.3 | Medium | 2024-01-11 |
All 33 known CVE vulnerabilities affecting LearnPress – WordPress LMS Plugin for Create and Sell Online Courses with full Chinese analysis, references, and POCs where available.